cbcvebase.

Debian Rails vulnerabilities

97 known vulnerabilities affecting debian/rails.

Total CVEs
97
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM49LOW12

Vulnerabilities

Page 1 of 5
CVE-2019-5418P1HIGHCVSS 7.5KEVPoCfixed in rails 2:5.2.2.1+dfsg-1 (bookworm)2019
CVE-2019-5418 [HIGH] CVE-2019-5418: rails - There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6... There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed. Scope: local bookworm: resolved (fixed in 2:5.2.2.1+dfsg-1) bullseye: resolved (fixed in 2:5.2.2.1+dfsg-1) forky: resolved (fixed in 2:
debian
CVE-2016-0752P1HIGHCVSS 7.5KEVPoCfixed in rails 2:4.2.5.1-1 (bookworm)2016
CVE-2016-0752 [HIGH] CVE-2016-0752: rails - Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.... Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. Scope: local bookworm: resolved (fixed in 2:
debian
CVE-2013-0156P1HIGHCVSS 7.5ExploitedPoCfixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-0156 [HIGH] CVE-2013-0156: rails - active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.... active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity
debian
CVE-2019-5420P1CRITICALCVSS 9.8PoCfixed in rails 2:5.2.2.1+dfsg-1 (bookworm)2019
CVE-2019-5420 [CRITICAL] CVE-2019-5420: rails - A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0... A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit. Scope: local bookworm: resolved (fixed in 2:5.2.2.1+dfsg-1) bullseye: r
debian
CVE-2020-8163P2HIGHCVSS 8.8PoCfixed in rails 2:5.2.0+dfsg-2 (bookworm)2020
CVE-2020-8163 [HIGH] CVE-2020-8163: rails - The is a code injection vulnerability in versions of Rails prior to 5.0.1 that w... The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. Scope: local bookworm: resolved (fixed in 2:5.2.0+dfsg-2) bullseye: resolved (fixed in 2:5.2.0+dfsg-2) forky: resolved (fixed in 2:5.2.0+dfsg-2) sid: resolved (fixed in 2:5.2.0+dfsg-2) trixie: res
debian
CVE-2013-0333P2HIGHCVSS 7.5PoCfixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-0333 [HIGH] CVE-2013-0333: rails - lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 an... lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability t
debian
CVE-2016-2098P2HIGHCVSS 7.3PoCfixed in rails 2:4.2.5.2-1 (bookworm)2016
CVE-2016-2098 [HIGH] CVE-2016-2098: rails - Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x bef... Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method. Scope: local bookworm: resolved (fixed in 2:4.2.5.2-1) bullseye: resolved (fixed in 2:4.2.5.2-1) forky: resolved (fixed in 2:4.2.5.2-1) sid: resolved (fixe
debian
CVE-2021-22881P2MEDIUMCVSS 6.1PoCfixed in rails 2:6.0.3.5+dfsg-1 (bookworm)2021
CVE-2021-22881 [MEDIUM] CVE-2021-22881: rails - The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers... The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot.
debian
CVE-2020-8165P2CRITICALCVSS 9.8fixed in rails 2:5.2.4.3+dfsg-1 (bookworm)2020
CVE-2020-8165 [CRITICAL] CVE-2020-8165: rails - A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, ... A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE. Scope: local bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1) bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1) forky: resolved (fixed in 2:5.2.4
debian
CVE-2021-44528P3MEDIUMCVSS 6.1PoCfixed in rails 2:6.1.4.6+dfsg-1 (bookworm)2021
CVE-2021-44528 [MEDIUM] CVE-2021-44528: rails - A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an... A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Scope: local bookworm: resolved (fixed in 2:6.1.4.6+dfsg-1) bullseye: resolved (fixed in
debian
CVE-2008-7248P3MEDIUMCVSS 6.8PoCfixed in rails 2.2.3-1 (bookworm)2008
CVE-2008-7248 [MEDIUM] CVE-2008-7248: rails - Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for... Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain. Scope: local bookworm: resolved (fixed in 2.2.3-1) bullseye: resolved (fix
debian
CVE-2022-21831P3CRITICALCVSS 9.8fixed in rails 2:6.1.4.7+dfsg-1 (bookworm)2022
CVE-2022-21831 [CRITICAL] CVE-2022-21831: rails - A code injection vulnerability exists in the Active Storage >= v5.2.0 that could... A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments. Scope: local bookworm: resolved (fixed in 2:6.1.4.7+dfsg-1) bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1) forky: resolved (fixed in 2:6.1.4.7+dfsg-1) sid: resolved (fixed in 2:6.1.4.7+dfsg-1) trixie: resolved (
debian
CVE-2022-32224P3CRITICALCVSS 9.8fixed in rails 2:6.1.6.1+dfsg-1 (bookworm)2022
CVE-2022-32224 [CRITICAL] CVE-2022-32224: rails - A possible escalation to RCE vulnerability exists when using YAML serialized col... A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE. Scope: local bookworm: resolved (fixed in 2:6.1.6.1+dfsg-1) bullseye: open forky:
debian
CVE-2025-24293P3CRITICALCVSS 9.2fixed in rails 2:6.1.7.10+dfsg-1~deb12u2 (bookworm)2025
CVE-2025-24293 [CRITICAL] CVE-2025-24293: rails - # Active Storage allowed transformation methods potentially unsafe Active Sto... # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrar
debian
CVE-2020-8264P3MEDIUMCVSS 6.1fixed in rails 2:6.0.3.4+dfsg-1 (bookworm)2020
CVE-2020-8264 [MEDIUM] CVE-2020-8264: rails - In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an applicat... In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware. Scope: local bookwor
debian
CVE-2009-2422P3CRITICALCVSS 9.8fixed in rails 2.3.5-1 (bookworm)2009
CVE-2009-2422 [CRITICAL] CVE-2009-2422: rails - The example code for the digest authentication functionality (http_authenticatio... The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending a
debian
CVE-2023-22794P3HIGHCVSS 8.8fixed in rails 2:6.1.7.3+dfsg-1 (bookworm)2023
CVE-2023-22794 [HIGH] CVE-2023-22794: rails - A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the s... A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious user input is passed to either the `annotate` query method, the `optimizer_hints` query method, or through the QueryLogs interface which automatically adds annotations, it may be sent to the database withinsufficient sanitization and be able to inject
debian
CVE-2013-0277P3CRITICALCVSS 10.0fixed in rails 2.3.14.1 (bookworm)2013
CVE-2013-0277 [CRITICAL] CVE-2013-0277: rails - ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote a... ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML. Scope: local bookworm: resolved (fixed in 2.3.14.1) bullseye: resolved (fixed in 2.3.14.1) forky: resolved (fixed in 2.3.14.1
debian
CVE-2012-6496P3HIGHCVSS 7.5fixed in rails 2.3.14.1 (bookworm)2012
CVE-2012-6496 [HIGH] CVE-2012-6496: rails - SQL injection vulnerability in the Active Record component in Ruby on Rails befo... SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls. Scope: local bookwo
debian
CVE-2014-3482P3HIGHCVSS 7.5fixed in rails 2:4.1.4-1 (bookworm)2014
CVE-2014-3482 [HIGH] CVE-2014-3482: rails - SQL injection vulnerability in activerecord/lib/active_record/connection_adapter... SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting. Scope: local bookworm: resolved (fixed in 2:4.1.4-1) bullseye: resolved (fixed in
debian
Debian Rails vulnerabilities | cvebase